Google releases yet another emergency Chrome security update

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • PCHF IT Feeds
    PCHF Bot
    • Jan 2015
    • 54585

    #1

    Google releases yet another emergency Chrome security update

    Following the release of version 100 of its browser, Google has released a new update for Chrome to fix a high-severity zero-day vulnerability that is being actively exploited in the wild.

    According to a new security advisory put out by the search giant, the company is aware that an exploit exists for this high-severity vulnerability tracked as CVE-2022-1364.


    https://cdn.mos.cms.futurecdn.net/ybbmQ8p4Q999AkMWkW8HLm.jpg


    Share your thoughts on Cybersecurity and get a free copy of the Hacker’s Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

    The bug itself is a confusion weakness in the Chrome V8 JavaScript engine and while these types of vulnerabilities usually lead to browser crashes after reading or writing memory out of buffer bounds, cybercriminals can also exploit them to execute arbitrary code on vulnerable systems.

    The vulnerability was discovered by Clément Lecigne from Google’s Threat Analysis Group who immediately reported it to the Google Chrome team. Although Google has observed this zero-day actively being exploited in the wild, the company has been tight lipped regarding any attacks. In its security advisory, it said that details about the bug and links will be “kept restricted until a majority of users are updated with a fix”.

    [IMG alt=“Google Chrome Manual Update”]https://cdn.mos.cms.futurecdn.net/4a...fqBmiU5h6g.jpg

    (Image credit: Google)
    [HEADING=1]Manually updating Chrome is your bet bet[/HEADING]

    Google Chrome 100.0.4896.127 for Windows, Mac and Linux will roll out in the next few weeks as an update.

    However, due to the high-severity of this vulnerability, security-conscious users can update Chrome immediately by going into the Chrome menu, heading to Help and clicking on About Google Chrome. Here, they’ll be able to manually install the update themselves as opposed to waiting for Google to roll it out.

    Read More

    > Google says it stopped North Korea hacking Chrome
    Google Chrome’s password manager is finally adding this must-have feature
    This Google Chrome challenger could be the best browser for private surfing
    For those that would rather wait though, Chrome will automatically check for new updates and install them the next time you close and relaunch the browser.

    This is the third zero-day vulnerability that has been discovered and patched in Chrome this year.

    [ul]
    [li]Keep all your software up to date with the best patch management tools[/li][/ul]

    Via BleepingComputer

    Continue reading…
Working...